Privacy Policy
Last updated August 6, 2026
VitalMed Supply sells medical supplies to pharmacies and clinics. This policy explains what we collect from the businesses we work with, why, and who else can see it. We have tried to write it so you can actually tell what the software does.
The short version
- We collect business contact details and order history. We do not collect patient information of any kind.
- We run no analytics, no advertising trackers, and no third-party scripts on this site.
- We use two cookies, both strictly necessary to sign you in and keep you safe. Neither follows you anywhere.
- We do not sell your information, and we do not share it for advertising.
Who we are
VitalMed Supply LLC, a Wyoming limited liability company, distributing medical supplies to pharmacies and clinics. Our mailing address is 12810 S Date St, Jenks, OK 74037. If you have a question about this policy or about information we hold, email sales@vitalmed.supply or call 479.790.8684.
What we collect
If you contact us through this site, we collect your name, your company, your email address, and optionally your phone number, which products you are interested in, and whatever you write in the message box.
If your business has a portal account, we hold your name and work email, your company’s billing and shipping details, the pricing agreed with your account, and the history of what you have ordered.
Automatically, we record the IP address of requests to our sign-in and contact endpoints, purely to limit how often those can be hit. Those records are deleted after twenty-four hours and are not used to build any profile of you.
We do not collect patient information. We supply consumables such as syringes, vials, and alcohol pads. Nothing in our portal asks for, stores, or transmits protected health information, and you should never send us any.
How you sign in
We do not use passwords and we do not store any. Signing in sends a six-digit code to your work email, which expires after ten minutes and can only be used once. Your session is held as a cookie whose value we store only as an irreversible hash, so a copy of our database would not let anyone sign in as you.
Staff sessions end after twelve hours without use, and in any case within seven days of the last activity we saw. Customer sessions end thirty days after their last use, because re-authenticating a pharmacy buyer every week is friction without a matching security benefit. Deactivating a login ends its sessions immediately.
Cookies
Two, and both are strictly necessary, which is why this site has no cookie banner asking you to accept anything optional. There is nothing optional to accept.
vm_sessionkeeps you signed in. It cannot be read by JavaScript and is sent only to this site.qbo_oauth_stateexists for fifteen minutes while an administrator connects our QuickBooks integration, and protects that step from being triggered by another website.
We run no analytics and no advertising or social media trackers. No third-party script loads on this site at all.
QuickBooks Online
With your authorization, we connect to your QuickBooks Online company to keep our records and your accounting in step. This connection is approved by someone with administrator rights on your QuickBooks and can be disconnected at any time, from your side or ours.
Through that connection we read:
- Your item records, from which we use and keep the names, codes, purchase costs, sales prices, and quantities on hand.
- Your company name, legal name, and country, which we use only to confirm the connection is working.
When an order ships, we create the matching invoice in your books, so what you sold and what your accounting says stay in step. We store a cached copy of the item information above so that browsing a catalog does not make a call to Intuit on every page view. We hold access tokens for the connection in our database, never in a browser.
Disconnecting stops all future access immediately, and we delete the stored connection tokens at that point. You can disconnect from your side in QuickBooks under connected apps, or ask us and we will do it and revoke our own access. Item details already copied into our catalog are part of our business records and are kept under the rest of this policy.
We do not use QuickBooks data for advertising, we do not sell it, and we do not share it with anyone outside the service providers listed below.
Who else sees your information
We use a small number of service providers to run the platform. They process information on our instructions and for no purpose of their own.
- Vercel, which hosts this website and the portal (United States).
- Neon, which hosts our database (United States).
- Resend, which delivers our email, including sign-in codes and order notifications.
- Intuit, for the QuickBooks connection described above, where your business has authorized one.
- ShipStation, for shipping labels and tracking, once shipping runs through it.
We may also disclose information if the law requires it, or to protect the rights and safety of our customers and our business.
We do not sell personal information and we do not share it for cross-context behavioral advertising.
Payments
We do not currently accept card payments through this portal, and we do not store card numbers anywhere. If that changes, payment details will be handled by a payment processor and this policy will be updated before the feature goes live.
Email we send
We email you to run your account: sign-in codes, order notifications, and replies to inquiries you send us. If you write to us through the contact form, our sales team will follow up with you; that is what the form is for.
We do not send marketing email. If that ever changes, every marketing message will include a working unsubscribe link and our mailing address, and opting out will never affect the account emails you need.
How long we keep things
Order records, invoices, and the account history behind them are kept for as long as we do business together and afterwards for as long as tax and commercial record-keeping obligations require. Website inquiries are kept while we follow them up and while the business relationship they may lead to continues. Rate-limiting records containing IP addresses are deleted after twenty-four hours. Sign-in codes expire in ten minutes.
Security
Traffic to this site is encrypted in transit, and our hosting and database providers encrypt what they store at rest. Sign-in session tokens are stored only as hashes, so they cannot be recovered from our records. Access to customer accounts is limited to the people at your business you ask us to give access to, and administrative accounts are created only from a command line by our own team, never through a web form. Deactivating a login ends any session it already had.
If a security incident affects your information, we will notify you as the law requires, and sooner where we can.
No system is perfectly secure, and we do not claim otherwise. If you believe an account has been compromised, contact us immediately at sales@vitalmed.supply.
Your choices
You can ask us what information we hold about you, ask us to correct it, or ask us to delete it, and we will do so unless we are required to keep it for tax or legal reasons. You can ask us to remove a portal login at any time. Depending on where you live, the law may give you additional rights over your information. Where a privacy law applies to us and to you, we will honor it.
Email sales@vitalmed.supply to make a request. We may need to confirm who you are first.
Children
This is a service for businesses. It is not directed at children, and we do not knowingly collect information from any child under thirteen. If you believe a child has given us information, tell us and we will delete it.
Changes
If we change this policy we will update the date at the top, and where the change is significant we will tell account holders by email rather than relying on you to notice.
See also our Terms of Service.

